CrySP Speaker Series on Privacy • Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment

Monday, October 5, 2026 2:00 pm - 3:00 pm EDT (GMT -04:00)

Please note: This talk will take place in DC 1304 and online.

Arash Shaghaghi, Associate Professor
School of Computer Science and Engineering, UNSW Sydney

Post-quantum cryptography (PQC) has evolved from a long-term planning concern into an operational priority. Following NIST’s standardization of PQC algorithms, governments and standards bodies published transition roadmaps outlining migration timelines, priority sectors, and deployment strategies. However, our survey of these policies reveals substantial divergence in technical prescriptions and urgency. It remains unclear how widely PQC has been adopted in practice and how policy differences translate into observable deployment outcomes.

To quantify trends in public-facing post-quantum TLS (PQ-TLS) adoption, we conducted three measurement rounds between July 2025 and March 2026, covering one million public HTTPS endpoints. Across these rounds, we established more than two billion TLS 1.3 handshakes from 11 globally distributed vantage points to characterize cryptographic negotiation behavior. Default hybrid key-exchange adoption rose from 31% to 49% over the period, with every observed post-quantum negotiation selecting X25519MLKEM768, but we find no verified deployment of post-quantum signature algorithms for authentication. Adoption is highly concentrated among endpoints attributed to managed infrastructure providers, which account for roughly 94% of observed deployment. Country and sector comparisons show limited correspondence between early deployment patterns and published transition timelines. Contrary to early experimental studies suggesting measurable overhead, we observe a median latency difference of zero milliseconds for hybrid key exchange in Internet settings. We further observe that PQC adoption frequently coexists with legacy TLS configurations.

Together, these findings highlight a gap between policy expectations and early deployment reality. I will walk through the measurement infrastructure, the main findings, and what the still-missing authentication half means for the next phase of the PQ-TLS transition.

Bio: Arash Shaghaghi is an Associate Professor in Cybersecurity and Founder of the Cyber Threat Intelligence (CTI) Lab at the School of Computer Science and Engineering, UNSW Sydney. His research spans network and system security, IoT security, and cyber threat intelligence, with recent publications at IEEE S&P, NDSS, WWW, DSN, and ACM IMC. His work has been funded by Cisco, the Cyber Security Cooperative Research Center (CSCRC), the Australian Research Data Commons (ARDC), the Australian Department of Defense, and the NSW Government.

He was selected for the 2023 Heidelberg Laureate Forum. He is an Associate Editor of Ad Hoc Networks and currently serves on the program committees of USENIX Security, RAID, and NDSS.


To attend this talk in person, please go to DC 1304. You can also attend virtually on Zoom.